PT-2026-98147 · Libde265 · Libde265

CVE-2026-88373

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libde265 versions prior to commit 4d45a6b
Description A NULL pointer dereference exists in the NAL parsing path. When the function de265 push NAL() is called with a zero-length NAL unit, the resulting NAL unit may retain a NULL backing buffer. This buffer is then passed as the destination argument to memcpy() within the NAL unit::set data() function. Even though the copy length is zero, this violates the nonnull requirement of memcpy(), leading to undefined behavior, process termination in UBSan-instrumented builds, and denial of service.
Recommendations Update to a version of libde265 that includes the fix implemented after commit 4d45a6b.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88373

Affected Products

Libde265